CVE-2026-32432
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-32432 is a Missing Authorization vulnerability in the WP Time Slots Booking Form WordPress plugin by CodePeople, classified under CWE-862. It allows unauthenticated network attackers to exploit incorrectly configured access control security levels to modify booking data. The vulnerability affects all versions of the plugin up to and including 1.2.42. It was published on March 13, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).

Technical details

The root cause is a Missing Authorization flaw (CWE-862), where certain plugin endpoints or actions fail to verify whether the requesting user has appropriate permissions before processing the request. This falls under the broader category of Broken Access Control, where incorrectly configured security levels allow unauthenticated users to invoke privileged functionality. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity — meaning any remote attacker can trigger the vulnerable code path without preconditions. The vulnerability was reported and coordinated through Patchstack (Patchstack, Feedly).

Impact

Successful exploitation allows an unauthenticated attacker to modify booking data on affected WordPress installations, compromising data integrity. There is no direct confidentiality or availability impact per the CVSS scoring (C:N, A:N), but tampered booking records could disrupt business operations, cause scheduling conflicts, or enable fraudulent reservations. The scope is limited to the affected WordPress site's booking functionality and does not directly facilitate lateral movement or privilege escalation (Feedly).

Exploitability

The vulnerability has a low EPSS score of approximately 0.017%, indicating a low current probability of active exploitation in the wild. No public proof-of-concept exploit code, exploit kit integration, or threat actor attribution has been reported at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the zero-authentication requirement and network accessibility make it relatively straightforward to exploit if a PoC were to emerge (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Time Slots Booking Form plugin (version ≤ 1.2.42) using tools like WPScan, Shodan, or by inspecting plugin directories (/wp-content/plugins/wp-time-slots-booking-form/).
  2. Identify unprotected endpoints: Review the plugin's registered AJAX actions or REST API endpoints that lack capability checks (e.g., check_user_logged_in, current_user_can() calls absent from handlers).
  3. Craft malicious request: Send an unauthenticated HTTP POST or GET request directly to the vulnerable endpoint (e.g., wp-admin/admin-ajax.php?action=<vulnerable_action>) with crafted parameters to modify booking records.
  4. Achieve unauthorized data modification: The server processes the request without verifying authorization, allowing the attacker to alter, delete, or inject booking slot data as desired (Patchstack).

Indicators of compromise

  • Network: Unexpected or repeated unauthenticated POST requests to wp-admin/admin-ajax.php with action parameters associated with the WP Time Slots Booking Form plugin from unknown or suspicious IP addresses.
  • Logs: WordPress access logs showing requests to booking-related AJAX actions without a valid session cookie or nonce; anomalous modification timestamps on booking records.
  • File System: Unexpected changes to booking data stored in the WordPress database (wp_* tables related to the plugin); no direct file system artifacts expected for this vulnerability type.
  • Application: Unexplained alterations to time slot availability, booking entries, or reservation records in the plugin's admin dashboard (Feedly).

Mitigation and workarounds

Plugin users should update the WP Time Slots Booking Form plugin to a version above 1.2.42 as soon as a patched release is made available by CodePeople. In the interim, site administrators can restrict access to wp-admin/admin-ajax.php for unauthenticated users via web application firewall (WAF) rules or by using a security plugin such as Wordfence or Patchstack to virtually patch the vulnerability. Disabling the plugin entirely until a fix is available is also a viable option for high-risk environments (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18039NONEN/A
  • essential-addons-for-elementor-lite
NoYesAug 14, 2026
CVE-2026-16810NONEN/A
  • bit-form
NoYesAug 14, 2026
CVE-2026-16739NONEN/A
  • epeken-all-kurir
NoNoAug 14, 2026
CVE-2026-15205NONEN/A
  • paymob-for-woocommerce
NoYesAug 14, 2026
CVE-2026-14290NONEN/A
  • embed-google-photos-album-easily
NoNoAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management